<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Johan Sydseter</title>
    <description>The latest articles on DEV Community by Johan Sydseter (@sydseter).</description>
    <link>https://dev.to/sydseter</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg</url>
      <title>DEV Community: Johan Sydseter</title>
      <link>https://dev.to/sydseter</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sydseter"/>
    <language>en</language>
    <item>
      <title>We are happy to announce the release of the OWASP Cornucopia Mobile App Edition v2.0. The latest edition is compatible with MASVS v2.1, MASTG v2.0, and MASWE v1.0, and features 80 threats that cover all the requirements, tests, and weaknesses of OWASP.</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Thu, 10 Sep 2026 06:54:46 +0000</pubDate>
      <link>https://dev.to/sydseter/we-are-happy-to-announce-the-release-of-the-owasp-cornucopia-mobile-app-edition-v20-the-latest-252c</link>
      <guid>https://dev.to/sydseter/we-are-happy-to-announce-the-release-of-the-owasp-cornucopia-mobile-app-edition-v20-the-latest-252c</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd" class="crayons-story__hidden-navigation-link"&gt;OWASP Cornucopia Mobile App Edition v2.0&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/owasp"&gt;
            &lt;img alt="OWASP® Foundation logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3468%2F0b3561bb-9ac3-413f-baaa-5014181e4b4d.jpg" class="crayons-logo__image" width="400" height="400"&gt;
          &lt;/a&gt;

          &lt;a href="/sydseter" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" alt="sydseter profile" class="crayons-avatar__image" width="799" height="747"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sydseter" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Johan Sydseter
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Johan Sydseter
                
                
              
              &lt;div id="story-author-preview-content-4615956" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sydseter" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" class="crayons-avatar__image" alt="" width="799" height="747"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Johan Sydseter&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/owasp" class="crayons-story__secondary fw-medium"&gt;OWASP® Foundation&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Sep 10&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd" id="article-link-4615956"&gt;
          OWASP Cornucopia Mobile App Edition v2.0
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/mobile"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;mobile&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/software"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;software&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            8 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>cybersecurity</category>
      <category>mobile</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>OWASP Cornucopia Mobile App Edition v2.0</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Thu, 10 Sep 2026 06:53:07 +0000</pubDate>
      <link>https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd</link>
      <guid>https://dev.to/owasp/owasp-cornucopia-mobile-app-edition-v20-3nnd</guid>
      <description>&lt;p&gt;&lt;em&gt;We are happy to announce the release of the &lt;a href="https://github.com/OWASP/cornucopia/releases/tag/v3.5.0" rel="noopener noreferrer"&gt;OWASP Cornucopia Mobile App Edition v2.0&lt;/a&gt;. The latest edition is compatible with &lt;a href="https://mas.owasp.org/MASVS/" rel="noopener noreferrer"&gt;MASVS v2.1&lt;/a&gt;, &lt;a href="https://mas.owasp.org/MASTG/" rel="noopener noreferrer"&gt;MASTG v2.0&lt;/a&gt;, and &lt;a href="https://mas.owasp.org/MASWE/" rel="noopener noreferrer"&gt;MASWE v1.0&lt;/a&gt;, and features 80 threats that cover all the requirements, tests, and weaknesses of the OWASP Mobile Application Security Project.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why would you use OWASP Cornucopia Mobile App Edition?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7r7t9n8752ymsvw9fxwu.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7r7t9n8752ymsvw9fxwu.jpg" alt="Mobile application security is no joke!" width="735" height="500"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;At Admincontrol, the &lt;a href="https://dev.to/owasp/how-to-pass-the-owasp-masvs-verification-by-design-2cf9"&gt;OWASP Cornucopia Mobile App Edition is used to implement mobile application security by design&lt;/a&gt;. Before building mobile apps and features, OWASP Cornucopia helps the team identify threats during the threat modeling and design phase. For example, during gameplay, a developer identifies that &lt;a href="https://owaspcornucopia.org/edition/mobileapp/AA3/2.0/en" rel="noopener noreferrer"&gt;card AA3&lt;/a&gt; should be considered during app development. Each  identified card includes a &lt;a href="https://owaspcornucopia.org/edition/mobileapp/AA3/2.0/en#mapping" rel="noopener noreferrer"&gt;mapping table&lt;/a&gt; showing which CAPEC™s, OWASP &lt;a href="https://mas.owasp.org/MASWE/" rel="noopener noreferrer"&gt;MASWEs&lt;/a&gt;, &lt;a href="https://mas.owasp.org/MASTG/best-practices/#" rel="noopener noreferrer"&gt;MASTG Best Practices&lt;/a&gt;, &lt;a href="https://mas.owasp.org/MASTG/knowledge/" rel="noopener noreferrer"&gt;MASTG Knowledge base&lt;/a&gt;, &lt;a href="https://mas.owasp.org/MASTG/" rel="noopener noreferrer"&gt;MASTG tests&lt;/a&gt;, and &lt;a href="https://mas.owasp.org/MASVS/" rel="noopener noreferrer"&gt;MASVS requirements&lt;/a&gt; apply when developing a specific mobile feature. This simplifies identifying mobile application security requirements during development and makes it possible to decide on security requirements during the development sprint in an agile, lean way. &lt;/p&gt;

&lt;p&gt;During gamification and threat modeling, the team identifies threats that naturally drive application security requirements. Doing this before sprint planning makes threat modeling and security requirement analysis part of the team's SDLC. In addition, it’s the team that gets to decide «what can go wrong» and «what we are going to do about it». Letting the team decide ensures alignment with the application security requirements and security goals and prevents scope creep and dissatisfied scrum masters. Security awareness and a security sprint scope are created as a result. Doing games and threat modeling before sprint planning builds engagement, alignment, and security awareness without pushback that could push security issues to the backlog and let them be forgotten.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why should I do this when I can use AI agents?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe5o0uff44x7zynfi5c0z.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe5o0uff44x7zynfi5c0z.webp" alt="AI Threat Modeling" width="800" height="336"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There is this quote from David Dunning where he says: "If you're incompetent, you can't know you're incompetent. The skills you need to produce a right answer are exactly the skills you need to recognize what a right answer is."&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;a href="https://www.psychologytoday.com/us/blog/dear-life-please-improve/202506/fighing-the-passive-learning-trap" rel="noopener noreferrer"&gt;«Fighting The Passive Learning Trap», Psychology Today&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;What do I mean by that? Well, let's say your AI agents have created a beautiful threat model and secure design for your application that requires you to implement «&lt;a href="https://www.ibm.com/think/topics/just-in-time-access" rel="noopener noreferrer"&gt;Just-In-Time Access&lt;/a&gt;», but then, during the development sprint, it clashes with one of the features that the product owner has been told to implement by the product manager. When asking your Claude-based AI agents to fix it, it takes an extraordinary amount of time and becomes really expensive. After it has finished, the AI agents' review comes back with 200 comments. The work never seems to finish, and the AI review agent, the AI threat modeling agent, and the AI Coding agent don’t seem to agree with each other. In the end, after a lengthy discussion with Claude, you understand that implementing Just-In-Time access is a much more extensive task than what you initially thought it was. After all, you didn’t have a clue about it in the first place. So what do you do? The product manager doesn’t give in; he wants his feature. Maybe Just-In-Time access isn’t that important after all? &lt;br&gt;
The feature ships, but the security remains underdeveloped. That is, until AI agents from North Korea come knocking.&lt;/p&gt;

&lt;p&gt;There are no shortcuts to learning. You need to know what is important and how to make the right decisions. &lt;br&gt;
AI agents can’t make the decisions for you. AI agents are sycophants. They will happily cheer you on even if you make the wrong choices. This is why we do threat modeling. Through the threat modeling process, the whole team learns «what can go wrong» and «what we are going to do about it». Offshoring your decision-making processes is a terrible risk management strategy that will lead your life to ruin.&lt;/p&gt;
&lt;h2&gt;
  
  
  Mobile App Edition v2.0
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F88hocuor5xffejhqn9pj.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F88hocuor5xffejhqn9pj.jpg" alt="OWASP® Cornucopia Mobile App Edition" width="800" height="602"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The latest edition is compatible with &lt;a href="https://mas.owasp.org/MASVS/" rel="noopener noreferrer"&gt;MASVS v2.1&lt;/a&gt;, &lt;a href="https://mas.owasp.org/MASTG/" rel="noopener noreferrer"&gt;MASTG v2.0&lt;/a&gt;, and &lt;a href="https://mas.owasp.org/MASWE/" rel="noopener noreferrer"&gt;MASWE v1.0&lt;/a&gt;, and features 80 threats that cover all the requirements, tests, and weaknesses of the OWASP Mobile Application Security Project.&lt;br&gt;
The deck has six suits of 13 cards plus two jokers, with the suit names taken from MASVS: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Platform &amp;amp; Code (PC)&lt;/li&gt;
&lt;li&gt;Authentication &amp;amp; Authorization (AA)&lt;/li&gt;
&lt;li&gt;Network &amp;amp; Storage (NS)&lt;/li&gt;
&lt;li&gt;Resilience (RS)&lt;/li&gt;
&lt;li&gt;Cryptography (CRM)&lt;/li&gt;
&lt;li&gt;Cornucopia (CM), which contains threats related to MASVS Privacy requirements, and where we have also added some nasty cards related to mobile malware. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The edition exists in English and has been translated into Hindi, Russian, and Ukrainian. &lt;br&gt;
To play the game online, visit &lt;a href="https://cornucopia.owasp.org" rel="noopener noreferrer"&gt;cornucopia.owasp.org&lt;/a&gt; and click on «Play online».&lt;/p&gt;
&lt;h2&gt;
  
  
  AI mobile development
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fx2hjmxpganm7sz72dgh5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fx2hjmxpganm7sz72dgh5.png" alt="OWASP Companion Edition v1.0" width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;With the new edition, you can also combine it with the OWASP Cornucopia Companion Edition. The new &lt;a href="https://cornucopia.owasp.org/edition/companion" rel="noopener noreferrer"&gt;OWASP Cornucopia Companion Edition&lt;/a&gt; complements the existing two editions. The &lt;a href="https://cornucopia.owasp.org/edition/companion" rel="noopener noreferrer"&gt;OWASP Cornucopia Companion Edition v1.0&lt;/a&gt; comes with 6 companion suits covering new topics:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Agentic AI (AAI)&lt;/li&gt;
&lt;li&gt;Automated Threats (BOT)&lt;/li&gt;
&lt;li&gt;Cloud (CLD)&lt;/li&gt;
&lt;li&gt;Frontend (FRE)&lt;/li&gt;
&lt;li&gt;Large Language Models (LLM)&lt;/li&gt;
&lt;li&gt;DevOps (DVO)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A suit in the companion deck may replace (or be used in addition to) suits in the existing Mobile App Edition so that players can add a specific focus to their threat modeling. Let’s say you are building an LLM mobile application and want to perform threat modeling and security requirement analysis specifically for Mobile and LLM. You would then use the OWASP Cornucopia Mobile App Edition and the LLM companion suite as your elected OWASP Cornucopia focus area.&lt;/p&gt;

&lt;p&gt;If you want to buy a physical version of the Companion Edition, go to &lt;a href="https://cybersecgames.com/pages/owasp-cornucopia-threat-modeling-collection" rel="noopener noreferrer"&gt;CyberSec Games&lt;/a&gt; where you can buy the 25th Anniversary Edition as it also comes with both the Website App Edition 3.0 and the new OWASP Cornucopia Companion Edition. The Mobile App Edition v2.0 is available for pre-order at: &lt;a href="https://cybersecgames.com/products/owasp-cornucopia-mobile-app-edition-threat-modeling-cards" rel="noopener noreferrer"&gt;https://cybersecgames.com/products/owasp-cornucopia-mobile-app-edition-threat-modeling-cards&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
  
  
  AI Threat Modeling with PHANTOM-B
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwo39aoa3wj4b8crynt1l.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwo39aoa3wj4b8crynt1l.jpeg" alt="PHANTOM-B, July, 2026, by Adam Shostack" width="800" height="492"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As the application security landscape shifts, Large Language Models (LLMs) and Agentic AI introduce entirely new threat vectors. To help you tackle these, the Cornucopia Companion suits for &lt;a href="https://cornucopia.owasp.org/edition/companion/LLM2/1.0/en#card" rel="noopener noreferrer"&gt;&lt;strong&gt;Large Language Models&lt;/strong&gt;&lt;/a&gt; and &lt;a href="https://cornucopia.owasp.org/edition/companion/AAI2/1.0/en" rel="noopener noreferrer"&gt;&lt;strong&gt;Agentic AI&lt;/strong&gt;&lt;/a&gt; have been upgraded. &lt;/p&gt;

&lt;p&gt;We have added &lt;strong&gt;PHANTOM-B&lt;/strong&gt; mapping to &lt;a href="https://cornucopia.owasp.org/edition/companion/AAIK/1.0/en#PHANTOM-B" rel="noopener noreferrer"&gt;each of these cards&lt;/a&gt;. If you check the help pages for the LLM and Agentic AI cards, you will now find detailed explanations for these mappings to help your team get familiar with AI Threat Modeling natively in your sessions.&lt;/p&gt;
&lt;h3&gt;
  
  
  What is PHANTOM-B?
&lt;/h3&gt;

&lt;p&gt;If you haven't read Adam Shostack's recent post on &lt;a href="https://shostack.org/blog/why-phantom-b/" rel="noopener noreferrer"&gt;Why PHANTOM-B?&lt;/a&gt;, PHANTOM-B is a tool designed to structure how you answer the question: &lt;em&gt;"What can go wrong?»&lt;/em&gt; (with the LLM parts of the system).&lt;/p&gt;

&lt;p&gt;Created by Adam Shostack and the Shostack + Associates team—and validated alongside hyperscalers and global financial institutions—it's a STRIDE-analogous mnemonic engineered specifically for LLMs. While vulnerability lists like the OWASP LLM Top 10 are fantastic for general awareness, they don't explicitly tell you how &lt;em&gt;your specific architecture&lt;/em&gt; will fail. &lt;/p&gt;

&lt;p&gt;PHANTOM-B is a repeatable, lightweight threat elicitation tool that focuses strictly on what engineering teams can control and influence, scaling complex generative AI behaviors into an actionable map.&lt;/p&gt;
&lt;h2&gt;
  
  
  Cornucopia, now 100% synced with AISVS v1.0
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9522jjb8re71vahn4n2i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9522jjb8re71vahn4n2i.png" alt="AISVS" width="800" height="693"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In case you missed it, AISVS - OWASP Artificial Intelligence Security Verification Standard was recently released as version 1.0, and we have made sure OWASP Cornucopia is correctly mapped to AISVS. This way, after you have figured out what can go wrong with LLMs and agentic systems during the threat modeling sessions, we can help you answer the question: &lt;em&gt;«What are we going to do about it?»&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  How to get those requirements into your issue tracking software
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" alt="Threat Dragon and EoP Games" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So you have done your threat modeling and security requirements analysis; what comes next? You need to create an issue the development team can work on, and add it to the development team's sprint. How do you do it? &lt;br&gt;
The OWASP Cornucopia project is creating a &lt;a href="https://cornucopia.owasp.org/api/docs" rel="noopener noreferrer"&gt;requirements API&lt;/a&gt; that lets you harvest the security requirements you want. After you have &lt;a href="https://dev.to/owasp/the-cornucopia-of-gamified-threat-modeling-1c9k"&gt;created your threat model in OWASP Threat Dragon&lt;/a&gt;, extract its JSON response, look up the threats you have identified, and find the corresponding security requirements by using the API, merge the results together, and generate your &lt;a href="https://cornucopia.owasp.org/how-to-play#Gameplay---Modelling-evil-user-stories" rel="noopener noreferrer"&gt;evil user stories&lt;/a&gt; by pushing the results to your issue tracking software just in time for the development team's next sprint.&lt;/p&gt;
&lt;h2&gt;
  
  
  OWASP Cornucopia is looking for sponsors
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvblf9raywn2omdatbvat.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvblf9raywn2omdatbvat.jpg" alt="Become a sponsor" width="800" height="308"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Calling all AppSec heroes, card sharks, and generous sponsors! 🃏&lt;/p&gt;

&lt;p&gt;By now, you probably think: «How can someone be crazy enough to do all this work for free?»&lt;br&gt;
You are right; it’s absolutely crazy. Just think about it. All this card design and security requirement mapping work is done manually without the use of AI. We have fitted all OWASP ASVS, MASVS, AISVS, MASTG, DSOMM, SAMM, Web/Agentic/LLM Top 10, CAPECs, Mitre Atlas, etc., etc. (&lt;a href="https://github.com/OWASP/cornucopia#the-cross-references-on-the-web-app-edition-deck-relate-to-the-following-versions-of-other-owasp-and-external-resources" rel="noopener noreferrer"&gt;look here for not even a full list&lt;/a&gt;) onto 240 playing cards divided on 3 decks that can be played both physically and digitally. It’s crazy, absolutely unique, lots of fun, and a practical solution that helps teams bake secure coding into everyday conversations. It turns threat modeling into something people actually want to do. Yes, really.&lt;br&gt;
But here’s the twist…&lt;br&gt;
The project is currently missing a sponsor.&lt;br&gt;
That means there’s a golden opportunity for a forward-thinking company to:&lt;/p&gt;

&lt;p&gt;-&amp;gt; Support an open, globally recognized OWASP project&lt;br&gt;
-&amp;gt; Help make secure development more accessible (and enjoyable!)&lt;br&gt;
-&amp;gt; Get your logo featured directly on the Cornucopia decks used by teams worldwide&lt;/p&gt;

&lt;p&gt;Imagine your brand on desks during threat modeling sessions, workshops, and security training worldwide.&lt;br&gt;
Not a bad place to be, right?&lt;/p&gt;

&lt;p&gt;Whether you're a security vendor, consultancy, or just passionate about improving software security—this is a chance to give back to the community and gain visibility where it matters.&lt;br&gt;
If that sounds interesting, now’s the perfect time to step in and deal yourself a winning hand.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Know a company that should jump on this? Tag them below&lt;/li&gt;
&lt;li&gt;Curious about sponsoring? Let’s get the conversation going&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Learn more at: &lt;a href="https://cornucopia.owasp.org/news/20260525-become-a-cornucopia-sponsor" rel="noopener noreferrer"&gt;https://cornucopia.owasp.org/news/20260525-become-a-cornucopia-sponsor&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Final words
&lt;/h2&gt;

&lt;p&gt;OWASP Cornucopia welcomes any input or improvements you're willing to share. For anyone wanting to share their opinion, please don't hesitate to &lt;a href="https://github.com/OWASP/cornucopia/issues" rel="noopener noreferrer"&gt;visit our repository&lt;/a&gt;, share your feedback, and, if appropriate, give us a star⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open-source projects, run industry-leading educational and training conferences, and meet through over 340 chapters worldwide.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>mobile</category>
      <category>security</category>
      <category>software</category>
    </item>
    <item>
      <title>We’re thrilled to bring you OWASP Cornucopia v3.4 with an update that expands how we identify threats, whether you're mapping out traditional web applications or diving headfirst into the latest AI architectures.</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Tue, 21 Jul 2026 08:16:37 +0000</pubDate>
      <link>https://dev.to/sydseter/were-thrilled-to-bring-you-owasp-cornucopia-v34-with-an-update-that-expands-how-we-identify-1npo</link>
      <guid>https://dev.to/sydseter/were-thrilled-to-bring-you-owasp-cornucopia-v34-with-an-update-that-expands-how-we-identify-1npo</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal" class="crayons-story__hidden-navigation-link"&gt;OWASP Cornucopia v3 with EoP and PHANTOM-B&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/owasp"&gt;
            &lt;img alt="OWASP® Foundation logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3468%2F0b3561bb-9ac3-413f-baaa-5014181e4b4d.jpg" class="crayons-logo__image" width="400" height="400"&gt;
          &lt;/a&gt;

          &lt;a href="/sydseter" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" alt="sydseter profile" class="crayons-avatar__image" width="799" height="747"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sydseter" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Johan Sydseter
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Johan Sydseter
                
                
              
              &lt;div id="story-author-preview-content-4191200" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sydseter" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" class="crayons-avatar__image" alt="" width="799" height="747"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Johan Sydseter&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/owasp" class="crayons-story__secondary fw-medium"&gt;OWASP® Foundation&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Jul 21&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal" id="article-link-4191200"&gt;
          OWASP Cornucopia v3 with EoP and PHANTOM-B
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/gamedev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;gamedev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cornucopia"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cornucopia&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            6 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>ai</category>
      <category>architecture</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>OWASP Cornucopia v3 with EoP and PHANTOM-B</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Tue, 21 Jul 2026 08:15:57 +0000</pubDate>
      <link>https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal</link>
      <guid>https://dev.to/owasp/owasp-cornucopia-v34-eop-help-pages-and-phantom-b-3lal</guid>
      <description>&lt;p&gt;&lt;strong&gt;We’re thrilled to bring you &lt;a href="https://github.com/OWASP/cornucopia/releases/tag/v3.4.0" rel="noopener noreferrer"&gt;OWASP Cornucopia v3.4&lt;/a&gt; with an update that expands how we identify threats, whether you're mapping out traditional applications or diving headfirst into the latest AI architectures.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Elevation of Privilege (EoP)
&lt;/h2&gt;

&lt;p&gt;One of the exciting updates in this release is the addition of the &lt;a href="https://cornucopia.owasp.org/edition/eop" rel="noopener noreferrer"&gt;Elevation of Privilege (EoP) deck&lt;/a&gt; to the Cornucopia Help Pages. The new help pages are directly linked from our online game engine Copi when you play EoP at copi.owasp.org&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2isc2pgqmw37u3ovwspe.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2isc2pgqmw37u3ovwspe.jpeg" alt="EoP" width="800" height="1423"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  We Need Your Help!
&lt;/h3&gt;

&lt;p&gt;While the game is live, we are actively looking for community contributors to help us with the help pages for each of the EoP cards. Specifically, we need security minds to help players better answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;What can go wrong?&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;What are we going to do about it?&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you have experience with EoP or want to flex your threat mitigation muscles, we would love your pull requests to help guide players!&lt;/p&gt;

&lt;p&gt;Why are we doing this? Well, first off, it is to give players the option to visit the EoP help pages while they are playing EoP at &lt;a href="//copi.owasp.org"&gt;copi.owasp.org&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpkxermhv2ksgbdp2uisr.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpkxermhv2ksgbdp2uisr.jpeg" alt="EoP at copi.owasp.org" width="800" height="983"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When playing EoP at &lt;a href="//copi.owasp.org"&gt;copi.owasp.org&lt;/a&gt;, you will now be able to click the «Need more info» links on each card, which will take you to the help pages, and we are looking for your expertise to fill them out.&lt;/p&gt;

&lt;h3&gt;
  
  
  Thanking Our GSoC Contributors
&lt;/h3&gt;

&lt;p&gt;I want to take a moment to extend a massive thank you to our Google Summer of Code (GSoC) student, Ayman Algamal. Ayman has taken on adding the EoP game to our card browser for OWASP Cornucopia. At a high level, this project aims to solve the current roadblock where OWASP Threat Dragon lacks the ability to integrate EoP into their EoP games threat modelling diagrams. By adding a fully browsable EoP deck and exposing the cards through the existing API, Ayman's work will cleanly unblock this integration. We hope this will help development teams to more easily use EoP during their threat modelling sessions. Read more about how further down!&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Threat Modelling with PHANTOM-B
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwo39aoa3wj4b8crynt1l.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwo39aoa3wj4b8crynt1l.jpeg" alt="PHANTOM-B, July, 2026, by Adam Shostack" width="800" height="492"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As we look at the shifting landscape of application security, Large Language Models (LLMs) and Agentic AI are introducing entirely new threat vectors. To help you tackle these, the Cornucopia Companion suits for &lt;a href="https://cornucopia.owasp.org/edition/companion/LLM2/1.0/en#card" rel="noopener noreferrer"&gt;&lt;strong&gt;Large Language Models&lt;/strong&gt;&lt;/a&gt; and &lt;a href="https://cornucopia.owasp.org/edition/companion/AAI2/1.0/en" rel="noopener noreferrer"&gt;&lt;strong&gt;Agentic AI&lt;/strong&gt;&lt;/a&gt; have been upgraded. &lt;/p&gt;

&lt;p&gt;We have officially added &lt;strong&gt;PHANTOM-B&lt;/strong&gt; mapping to &lt;a href="https://cornucopia.owasp.org/edition/companion/AAIK/1.0/en#PHANTOM-B" rel="noopener noreferrer"&gt;each of these cards&lt;/a&gt;. If you check the help pages for the LLM and Agentic AI cards, you will now find detailed explanations for these mappings to help your team get familiar with AI Threat Modelling natively in your sessions.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is PHANTOM-B?
&lt;/h3&gt;

&lt;p&gt;If you haven't read Adam Shostack's recent post on &lt;a href="https://shostack.org/blog/why-phantom-b/" rel="noopener noreferrer"&gt;Why PHANTOM-B?&lt;/a&gt;, PHANTOM-B is a tool designed to structure how you answer the question: &lt;em&gt;"What can go wrong?»&lt;/em&gt; (with the LLM parts of the system).&lt;/p&gt;

&lt;p&gt;Created by Adam Shostack and the Shostack + Associates team—and validated alongside hyperscalers and global financial institutions—it serves as a STRIDE-analogous mnemonic specifically engineered for LLMs. While vulnerability lists like the OWASP LLM Top 10 are fantastic for general awareness, they don't explicitly tell you how &lt;em&gt;your specific architecture&lt;/em&gt; will fail. &lt;/p&gt;

&lt;p&gt;PHANTOM-B provides a repeatable, lightweight threat elicitation tool that focuses strictly on what engineering teams can actually control and influence, scaling down complex generative AI behaviours into an actionable map.&lt;/p&gt;

&lt;p&gt;Seats are filling up fast for Shostack + Associates Threat Modelling Intensive with Complete AI at this year’s Black Hat conference. If you are interested in knowing more about AI Threat Modelling and are in the vicinity, you should not forget to sign up.&lt;/p&gt;

&lt;p&gt;Registrations for their course is apparently still open! &lt;a href="https://blackhat.com/us-26/training/schedule/index.html#adam-shostacks-threat-modeling-intensive-with-complete-ai-51473?trk=public_post_comment-text" rel="noopener noreferrer"&gt;https://blackhat.com/us-26/training/schedule/index.html#adam-shostacks-threat-modeling-intensive-with-complete-ai-51473?trk=public_post_comment-text&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Cornucopia, now 100% synced with AISVS v1.0
&lt;/h2&gt;

&lt;p&gt;In case you missed it, AISVS - OWASP Artificial Intelligence Security Verification Standard was recently released as version 1.0, and we have made sure OWASP Cornucopia is correctly mapped to AISVS This, so that after you have figured out what can go wrong with LLM and Agentic during the threat modeling sessions, we can help you answer the question: &lt;em&gt;«What are we going to do about it?»&lt;/em&gt; &lt;/p&gt;

&lt;p&gt;A special thanks to Mayur Agnihotri for adding AISVS v1 &lt;a href="https://github.com/OWASP/AISVS/blob/main/1.0/en/0x10-C09-Orchestration-and-Agentic-Action.md#c92-high-impact-action-approval-and-irreversibility-controls" rel="noopener noreferrer"&gt;“High-Impact Action Approval and Irreversibility Controls”&lt;/a&gt; to the &lt;a href="https://cornucopia.owasp.org/edition/companion/AAIK/1.0/en#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;Agentic AI cards&lt;/a&gt; and to Adarsh Kumar for continuing pushing out bug fixes. You both rock!&lt;/p&gt;

&lt;h2&gt;
  
  
  Smarter, Smoother Game Sessions
&lt;/h2&gt;

&lt;p&gt;Finally, we know that scheduling a full threat modelling session with your entire team isn't always easy, and sometimes network connections and web browsers fail. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft6rledwx22q2fmzusevx.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft6rledwx22q2fmzusevx.jpeg" alt="Save Player state" width="800" height="1440"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;To improve the player experience, we have upgraded game sessions by saving the session state &lt;strong&gt;server-side&lt;/strong&gt;. In addition to stability, we have introduced the concept of &lt;strong&gt;sharing your card hand&lt;/strong&gt;. If you run out of time or have an emergency, you can simply hand off your cards so another team member can seamlessly take over your spot.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzvpj2bicwa86x9nk8c75.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzvpj2bicwa86x9nk8c75.png" alt="Share you Cornucopia hand" width="800" height="423"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can’t wait for you to try out 3.4.0. Grab your team, deal your hands, and let’s make threat modelling fun again!&lt;/p&gt;

&lt;h2&gt;
  
  
  Threat Dragon and EoP Games
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" alt="Threat Dragon and EoP Games" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When choosing a tool for publishing our threat model, we chose &lt;a href="https://www.threatdragon.com/#/" rel="noopener noreferrer"&gt;OWASP Threat Dragon&lt;/a&gt;. OWASP Threat Dragon is a free, open-source, cross-platform threat modelling application. It is used to create threat modelling diagrams and list threats for elements within the diagrams. Mike Goodwin created Threat Dragon as an open-source community project that provides an intuitive, accessible way to model threats.&lt;/p&gt;

&lt;p&gt;OWASP Threat Dragon recently released this possibility in v2.6. This was just the start of integration between the two projects. In v2.7 of OWASP Threat Dragon, we will make both the OWASP Cornucopia Companion Edition and Elevation of Privilege available from Threat Dragon!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" alt="How to choose to create a OWASP Cornucopia threat model" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It's now possible to create your OWASP Cornucopia Threat Model directly in OWASP Threat Dragon. When creating a new diagram for your threat model, simply choose to create an EoP Games diagram. We chose to call the diagram EoP Games for two reasons. One, OWASP Cornucopia is derived from the &lt;a href="https://shostack.org/games/elevation-of-privilege" rel="noopener noreferrer"&gt;Elevation of Privilege game&lt;/a&gt; created by Adam Shostack. Second, we don't want to stop with OWASP Cornucopia. We also want to add other EoP games, such as the original Elevation of Privilege game.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" alt="Create a OWASP Cornucopia threat" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Once you have created an EoP Games diagram, you can add OWASP Cornucopia threats to your threat model. The specific threat you add will get a link reference to the &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#Threat-Modeling" rel="noopener noreferrer"&gt;OWASP Cornucopia website&lt;/a&gt;, where you will find guidance on threat modelling and STRIDE, which will help you in identifying what can go wrong and what to do about it. You can also find a &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;complete mapping&lt;/a&gt; to &lt;a href="https://cornucopia.owasp.org/taxonomy/asvs-4.0.3/02-authentication/05-credential-recovery#V2.5.2" rel="noopener noreferrer"&gt;OWASP ASVS&lt;/a&gt;, &lt;a href="https://devguide.owasp.org/en/04-design/02-web-app-checklist/06-digital-identity/#1-authentication-a" rel="noopener noreferrer"&gt;OWASP Developer Guide&lt;/a&gt;, and all &lt;a href="https://cornucopia.owasp.org/taxonomy/capec-3.9" rel="noopener noreferrer"&gt;relevant CAPECs&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" alt="OWASP Corncupia Website" width="800" height="737"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Final words
&lt;/h2&gt;

&lt;p&gt;OWASP Cornucopia welcomes any input or improvements you might be willing to share with us. For anyone wanting to share their opinion, please don't hesitate to &lt;a href="https://github.com/OWASP/cornucopia/issues" rel="noopener noreferrer"&gt;visit our repository&lt;/a&gt;, share your feedback, and, if appropriate, give us a star⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 340 chapters worldwide.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>gamedev</category>
      <category>security</category>
      <category>cornucopia</category>
    </item>
    <item>
      <title>DBD Cornucopia is now available to play online!</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Wed, 17 Jun 2026 12:22:44 +0000</pubDate>
      <link>https://dev.to/owasp/dbd-cornucopia-is-now-available-to-play-online-4f83</link>
      <guid>https://dev.to/owasp/dbd-cornucopia-is-now-available-to-play-online-4f83</guid>
      <description>&lt;p&gt;&lt;strong&gt;In development, we are used to understanding threat modelling as a structured method to make applications and other software secure. And in this, “secure” usually means to protect against adverse events and their associated harms as they impact the system (e.g. to maintain availability), its data (e.g. to protect its confidentiality) and the organisation more widely (e.g. to ensure continued operation). OWASP Cornucopia's three editions (Website App, Mobile App and Companion) all help threat modelling from this perspective.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But assessments of threats can also use different perspectives. Developers may come across privacy impact assessments (PIAs), where threats to users' data and the impact on those users are paramount. PIAs may additionally examine harms to organisations, third parties and wider society.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.digitalbenefits.uk/number1/" rel="noopener noreferrer"&gt;Negative impacts on benefit claimants&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;In recent years, Colin Watson, who created OWASP Cornucopia in 2012, undertook a PhD at Newcastle University, UK. This examined how the digital implementation of e-government services impacts citizens. The research's scope was digitisation of social protection cash payments (in the UK called “welfare benefits”) and those working-age citizens who apply for, and possibly receive, the support payments (in the UK known as “benefit claimants”). The PhD used case studies of Universal Credit (UC), which is an income-related minimum resource payment, and, to a lesser extent, of Personal Independence Payment (PIP), an invalidity-related social protection payment. The research identified how many requirements for digitised services are not defined in government legislation or regulation, leading to what can be somewhat arbitrary “digital discretion” during design, implementation and operation. And many of these decisions can have &lt;a href="https://www.digitalbenefits.uk/number1/" rel="noopener noreferrer"&gt;negative impacts on benefit claimants&lt;/a&gt;. Following completion of the PhD, Colin Watson gathered together all the harms identified that can arise through the choices made during the software development lifecycle. These are far broader and deeper than the few commonly referred to accessibility matters (which can sometimes also be constrained to concerns about the UI).&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.digitalbenefits.uk" rel="noopener noreferrer"&gt;“Digital Benefits and Disbenefits (DBD Cornucopia)”&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;These harms have now also been converted into a Cornucopia-style deck of cards, to help teams identify negative impacts on the service users, and thus to provide requirements which avoid or minimise such harms. The deck is called “Digital Benefits and Disbenefits Cornucopia” (DBD Cornucopia) and uses the same game method.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.digitalbenefits.uk/deck" rel="noopener noreferrer"&gt;The Card Deck&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;Whilst the deck's threat descriptions, harm explanations and examples on the website reference use UK-specific language like “welfare benefit” instead of “social protection payment”, and “claimants” instead of “service users” or “citizens”, the threats are easily understandable for other jurisdictions, and other types of e-government services. Like OWASP Cornucopia, DBD Cornucopia is open source and free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 licence, so you can copy, distribute and transmit the work, and you can adapt it and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one. Make your own version!&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://copi.owasp.org" rel="noopener noreferrer"&gt;The Online Cornucopia Game Engine - Copi&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpipvfcfpojyd743865ab.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpipvfcfpojyd743865ab.jpg" alt="DBD Cornucopia - Copi" width="800" height="983"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The original OWASP Cornucopia was primarily comprised of word-processing documents. Due to the efforts in recent years by many generous volunteers and organisations to codify OWASP Cornucopia, DBD Cornucopia's threat data has been added to its repository. This means that, because of the project's &lt;a href="https://copi.owasp.org" rel="noopener noreferrer"&gt;integrated gaming engine Copi&lt;/a&gt;, the deck is now available for teams to play digitally online.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.digitalbenefits.uk/resources/documents/dbd-deck-1v00c.pdf" rel="noopener noreferrer"&gt;Printing&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Finkg807etgylkg6ndetg.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Finkg807etgylkg6ndetg.jpg" alt="DBD Cornucopia box" width="800" height="754"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Colin Watson had a small number of DBD Cornucopia decks printed to distribute to UK government departments, charities which campaign in this area, and academics undertaking research in the disciplines of service design and human-computer interaction. The first professionally printed OWASP Cornucopia deck in 2013 was distributed in a box which resembled a pack of cigarettes labelled with health warnings. Acknowledging that idea and the domestic nature of the harms, the physical DBD Cornucopia box is presented in the style of a powdered laundry detergent package, based on the notion that reducing harms is, in some way, cleaning up the e-government service. Sometimes humour is also necessary to counteract harms, and fun can help awareness and encourage use of service-user-oriented threat modelling.&lt;/p&gt;

&lt;p&gt;The high-res design files are all available for download and print at &lt;a href="https://www.digitalbenefits.uk/cornucopia/" rel="noopener noreferrer"&gt;www.digitalbenefits.uk/cornucopia&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;NB: DBD Cornucopia is not an OWASP project. &lt;/p&gt;

</description>
      <category>gamedev</category>
      <category>security</category>
      <category>appsec</category>
      <category>threatmodeling</category>
    </item>
    <item>
      <title>Yes! It’s time to party!

Again!! You may ask, but this time we have combined the strength of the OWASP Foundation’s open-source projects. 25 years of accumulated knowledge and wisdom distilled onto 158 playing cards.</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Mon, 11 May 2026 08:18:14 +0000</pubDate>
      <link>https://dev.to/sydseter/yes-its-time-to-party-again-you-may-ask-but-this-time-we-have-combined-the-strength-of-the-516c</link>
      <guid>https://dev.to/sydseter/yes-its-time-to-party-again-you-may-ask-but-this-time-we-have-combined-the-strength-of-the-516c</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984" class="crayons-story__hidden-navigation-link"&gt;Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/owasp"&gt;
            &lt;img alt="OWASP® Foundation logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3468%2F0b3561bb-9ac3-413f-baaa-5014181e4b4d.jpg" class="crayons-logo__image" width="400" height="400"&gt;
          &lt;/a&gt;

          &lt;a href="/sydseter" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" alt="sydseter profile" class="crayons-avatar__image" width="799" height="747"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sydseter" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Johan Sydseter
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Johan Sydseter
                
                
              
              &lt;div id="story-author-preview-content-3628235" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sydseter" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" class="crayons-avatar__image" alt="" width="799" height="747"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Johan Sydseter&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/owasp" class="crayons-story__secondary fw-medium"&gt;OWASP® Foundation&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;May 11&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984" id="article-link-3628235"&gt;
          Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/gamedev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;gamedev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/appsec"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;appsec&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              1&lt;span class="hidden s:inline"&gt;&amp;nbsp;comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            10 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>ai</category>
      <category>security</category>
      <category>appsec</category>
      <category>gamedev</category>
    </item>
    <item>
      <title>Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Mon, 11 May 2026 01:27:15 +0000</pubDate>
      <link>https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984</link>
      <guid>https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984</guid>
      <description>&lt;p&gt;&lt;strong&gt;Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What are we working on?&lt;/li&gt;
&lt;li&gt;What can go wrong?&lt;/li&gt;
&lt;li&gt;What are we going to do about it?&lt;/li&gt;
&lt;li&gt;Did we do a good job?&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  OWASP Cornucopia v3.0
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fk0hjx4i4t1zmevfoemgq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fk0hjx4i4t1zmevfoemgq.png" alt="OWASP Cornucopia Website App Edition v3.0" width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In order to support that second question in particular, we have released the next version of &lt;a href="https://github.com/OWASP/cornucopia/releases/tag/v3.0.0" rel="noopener noreferrer"&gt;OWASP Cornucopia v3.0&lt;/a&gt;.&lt;br&gt;
If you would like to buy a professional physical copy of v3.0, you can do so at &lt;a href="https://cybersecgames.com/pages/owasp-cornucopia-threat-modeling-collection" rel="noopener noreferrer"&gt;CyberSec Games&lt;/a&gt;. We would suggest buying the 25th anniversary edition as it also comes with both the Website App Edition 3.0 and the new OWASP Cornucopia Companion Edition, specifically made to be used together as an expansion. You can also download the design files from the release and take them to your local printer or print them yourself.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fni4jgw3w1qrgnke9bhzv.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fni4jgw3w1qrgnke9bhzv.jpg" alt="The 25th anniversay edition" width="799" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://cornucopia.owasp.org/about" rel="noopener noreferrer"&gt;OWASP Cornucopia&lt;/a&gt; is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional, and formal development processes. It is language, platform, and technology-agnostic.&lt;br&gt;
The formerly titled “Cornucopia — Ecommerce Website Edition” was renamed in v2.0 to “Cornucopia — Website App Edition”. This edition was originally created in August 2012, released as v1.0 in February 2013, and has undergone several minor updates/releases over the following ten to fifteen years. This has been substantially updated in v2.0, in which the most noticeable change was an update of the OWASP ASVS mapping from ASVS v3.0 to v4.0, together with the creation of translations into six languages (EN, ES, FR, NL, NO-NB, and PT-BR) due to the efforts of past and current volunteers.&lt;/p&gt;

&lt;p&gt;The new version, available in 11 languages (EN, ES, FR, HI, NL, NO-NB, PT-PT, PT-BR, RU, UK, IT), includes all new cards and text that cover all OWASP ASVS 5.0 requirements and links them to more than &lt;a href="https://cornucopia.owasp.org/edition/webapp/VEK/3.0/en#Mappings" rel="noopener noreferrer"&gt;200 unique common attack patterns (CAPEC™)&lt;/a&gt;. Each of the common attack patterns will have a unique set of ASVS 5.0 requirements, which means that you never need to stop playing the game! You will always be able to return to the same card to discover new threats and security requirements to consider when building your software; that's the Cornucopia way.&lt;/p&gt;

&lt;p&gt;We have also &lt;a href="https://cornucopia.owasp.org/api/docs" rel="noopener noreferrer"&gt;created an API&lt;/a&gt; where you can find, programmatically, all requirements connected to each card together with a complete mapping between CAPECs and ASVS 5.0 requirements so that you can automate your threat modeling and requirement analysis processes. If you want to know more about the latest additions to the Website App Edition v3.0, read all about it on our blog post "&lt;a href="https://dev.to/owasp/the-cornucopia-of-gamified-threat-modeling-1c9k"&gt;The Cornucopia of Gamified Threat Modeling&lt;/a&gt;"&lt;/p&gt;
&lt;h2&gt;
  
  
  OWASP Cornucopia Companion Edition v1.0
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fx2hjmxpganm7sz72dgh5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fx2hjmxpganm7sz72dgh5.png" alt="OWASP Companion Edition v1.0" width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Today, we are publishing a brand new &lt;a href="https://cornucopia.owasp.org/edition/companion" rel="noopener noreferrer"&gt;OWASP Cornucopia Edition&lt;/a&gt; to complement the existing two editions. The &lt;a href="https://cornucopia.owasp.org/edition/companion" rel="noopener noreferrer"&gt;OWASP Cornucopia Companion Edition v1.0&lt;/a&gt; comes with 6 companion suits covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO). A suit in the companion deck may replace (or be used in addition to) suits in the existing Website Edition so that the players can add a specific focus to their threat modeling: For example, say you are building an LLM application and want to perform threat modeling and security requirement analysis specifically for LLM. You would then use the OWASP Cornucopia Website Edition and the LLM companion suit as your elected OWASP Cornucopia focus area. The new version is immediately available online at &lt;a href="https://copi.owasp.org" rel="noopener noreferrer"&gt;copi.owasp.org&lt;/a&gt; and for sale at &lt;a href="https://cybersecgames.com/pages/owasp-cornucopia-threat-modeling-collection" rel="noopener noreferrer"&gt;CyberSec Games&lt;/a&gt;. You can also download the design files from &lt;a href="https://github.com/OWASP/cornucopia/releases/tag/v3.0.0" rel="noopener noreferrer"&gt;the latest release&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;To commemorate the OWASP Foundation's 25th anniversary, we have also designed the case, leaflet, and cards specifically to celebrate the anniversary and OWASP's achievements within the field of application security and software engineering. We will also be attending the OWASP Global AppSec 2026 in Vienna, where we will be demoing the game for anyone who wants to come and play with us.&lt;/p&gt;

&lt;p&gt;We feel this is only the start; each year, OWASP Cornucopia resellers distribute 1,000 games to teams worldwide. At copi.owasp.org, more than 500 users conduct threat modeling for mobile applications, agentic AI, automated threats, cloud, identity management, large language models, and SDL processes every month. In the coming time, we at OWASP Cornucopia will work towards promoting threat modeling and games to change the security culture at software companies worldwide.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn2cph7t5abkkqvmqd1tu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn2cph7t5abkkqvmqd1tu.png" alt="Copi users" width="800" height="481"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Why a companion edition?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fiixglrhdou5yp6m7b94f.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fiixglrhdou5yp6m7b94f.png" alt="Threat modeling isn't only for security people" width="800" height="336"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The time when development teams could focus only on web development is long gone. Modern software development and sprint planning often include implementing integrations towards large language models, AI agents, and DevOps pipelines through full-stack development. In such an environment, security requirements are constantly shifting from sprint to sprint. Therefore, the only possibility is choosing an agile and collaborative approach to threat modeling that supports including a large number of people with various backgrounds, experiences, and knowledge.&lt;br&gt;
The OWASP Cornucopia Companion Edition was created to accommodate this. A big, beautiful Excel document can never replace a collaborative approach to threat modeling that includes the opinions of everyone on the development team. To avoid having the threat modeling and security design processes become an exercise in superficial ISO compliance, you need to empower your development teams to work together to come up with a secure design. Such a process requires ingenuity, to think out of the box, and to make unpopular decisions that may affect the delivery schedule of a development project. Neither an Excel document nor an ISO 27001 policy will ever get a development team to do that.&lt;/p&gt;

&lt;p&gt;Failing to regularly assess your security isn't only costly; it can leave you vulnerable to threats. Several companies have implemented OWASP Cornucopia as part of their SDLC and use it for security requirements analysis, threat modeling, and secure design for every sprint and every user story. You should do the same! Don't let your business spiral out of control; consciously assess how you are doing by continuously threat-modeling your applications and infrastructure. To get started scaling your threat modeling efforts, OWASP Cornucopia and its companion edition are the perfect tools.&lt;/p&gt;

&lt;p&gt;We want to thank all project leaders and contributors to the OWASP projects who have provided valuable input and guidance on the OWASP Top 10, OWASP AISVS, OWASP MAS, OWASP Cumulus, OWASP Threat Dragon and the OWASP GenAI Security project. It's thanks to these projects, and many more, that we can deliver to you the OWASP gamified approach to threat modeling and requirement analysis.&lt;br&gt;
We also want to thank the people and contributors to Mitre's Common Attack Pattern Enumeration and Classification (CAPEC™) and Atlas, together with CSA Cloud Controls Matrix, which are all used in the cross-references provided.&lt;/p&gt;
&lt;h2&gt;
  
  
  Walk that walk, talk that talk
&lt;/h2&gt;

&lt;p&gt;With this latest version of OWASP Cornucopia, we are making it more than a game; it has become a fully fledged threat modeling tool. It doesn’t just feed into your threat modeling process; it drives it, and it doesn’t just work; it scales! A long-time project contributor, previously working at Banco de Crédito BCP, used OWASP Cornucopia to train hundreds of people in using &lt;a href="https://cybersecgames.com/blogs/case-studies/identifying-abuse-before-designing-architecture-embedding-game-based-threat-modelling-into-agile-delivery-at-a-major-latin-american-bank" rel="noopener noreferrer"&gt;OWASP Cornucopia for threat modeling&lt;/a&gt;.&lt;br&gt;
Several companies, such as Admincontrol AS, a Euronext subsidiary, are using it as part of their custom development methodology and have made it the &lt;a href="https://cybersecgames.com/blogs/case-studies/case-study-scaling-threat-modelling-through-gamification-at-admincontrol" rel="noopener noreferrer"&gt;primary mechanism for structured threat elicitation&lt;/a&gt;.  &lt;/p&gt;

&lt;p&gt;"Continuous Gamified threat modeling", done the OWASP way, has been tested and proven to work and is generally welcomed by ISO auditors. Not only is it welcomed, but auditors also love to hear about how it can be used to create engagement and change the culture of the companies that make use of it. This, according to Admincontrol, which has been audited 4 times using all 97 controls from ISO 27001/27002 as part of their information security management system. "Continuous Gamified Threat Modeling" is about assisting software development teams in identifying security requirements in Agile, conventional, and formal development processes through continuous gamification and threat modeling for every feature and every release. Don't apologize for designing before coding, it's called thinking!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flkhqpmt7dioxzsbqxcuh.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flkhqpmt7dioxzsbqxcuh.jpg" alt="Don't apologize for designing before coding, it's called thinking!" width="800" height="464"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And the developers? They love it! At the company I work for (Admincontrol), they always send out an anonymous survey to gather team feedback.&lt;br&gt;
The aggregate score for how satisfied respondents have been with all sessions they've held since they started to use OWASP Cornucopia in 2023 is 4.5 out of 5, which is the maximum. When asked how relevant the session was to the participant's job, the average score was 4.7 out of 5.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnud8608d8ujtj6fccdg5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnud8608d8ujtj6fccdg5.png" alt="Relevant for your job" width="800" height="395"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqcqi7p5h06plms4re4kn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqcqi7p5h06plms4re4kn.png" alt="How satisified are you?" width="799" height="375"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The point here is not just to do your initial security risk assessment and be done with it, but to continuously look for new threats as you improve your software, in line with the &lt;a href="https://www.threatmodelingmanifesto.org/" rel="noopener noreferrer"&gt;Threat Modeling Manifesto&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;"Continuous Threat Modeling", a term described in "&lt;a href="https://www.amazon.com/Threat-Modeling-Identification-Avoidance-Secure/dp/1492056553" rel="noopener noreferrer"&gt;Threat Modeling: A Practical Guide for Development Teams&lt;/a&gt;", is essential to keep your applications and infrastructure secure as you expand your system with new features and machines and increase the attack surface. Gamification can help you get started doing just that. So why would you want to continuously threat model your infrastructure and applications? Isn't it enough to just do a thorough check-up now and then? &lt;a href="https://cybersecgames.com/blogs/case-studies/case-study-scaling-threat-modelling-through-gamification-at-admincontrol" rel="noopener noreferrer"&gt;Admincontrol thought so as well&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;Admincontrol used threat modeling to design its applications. They have large sessions that they run once a year and several smaller sessions for each sprint. They define Jira issues to mitigate these threats and assign them directly to the development team's backlog. Then they have security backlog grooming once a month with the product owners, where they discuss directly with them how they can resolve these issues.&lt;br&gt;
The first graph shows the resolution time for Jira issues created during the annual threat modeling session. The second graph shows the resolution of Jira issues for the threat modeling they do each sprint.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F97x4rhidmqm26pwb6nd5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F97x4rhidmqm26pwb6nd5.png" alt="Large Threat Modeling Sessions" width="800" height="554"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3taf1mmkdlsu2iog8me0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3taf1mmkdlsu2iog8me0.png" alt="Small Threat Modeling Sessions" width="800" height="553"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As shown in the first graph, the resolution time is increasing. This is because they had Jira issues that were defined but never resolved. Some of the issues had taken nearly 3 years to resolve. &lt;br&gt;
The second graph shows an increase in resolution time. This is because Admincontrol had a component that didn't get finalized. It stayed on the drawing board, but the threat modeling was done, so the resolution time spiked. There are no data prior to 2023, as they didn't keep this form of statistics before then. On average, the resolution time for the short threat modeling sessions were ca. 3 months. This usually coincided with the frequency of their minor releases, which included new features.&lt;/p&gt;

&lt;p&gt;If you do long, large sessions, you run the risk of doing threat modeling irregularly, meaning you will have issues you will never be able to solve, and issues meant to improve security will stay in the development team's backlog forever, never to see the light of day. If you think technical debt is scary, wait until you see your security debt.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnhsd0flryamsuj6vj1az.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnhsd0flryamsuj6vj1az.jpg" alt="Sec Debt" width="800" height="539"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Credits
&lt;/h2&gt;

&lt;p&gt;We want to thank everyone who has made this possible. Especially, we want to thank&lt;/p&gt;

&lt;p&gt;Adrian Sroka, for bringing us the Agentic AI, Cloud, and Frontend suits for the new game and creating online pages and mapping his threats to OWASP AISVS, AITG, Top 10 Agentic Apps, and Top 10 for LLM, Mitre Atlas, and STRIDE.&lt;/p&gt;

&lt;p&gt;Mateusz Hubala, for bringing us the DevOps suit for the game and creating online pages and mapping his threats to OWASP SAMM and DSOMM, CAPEC, and STRIDE.&lt;/p&gt;

&lt;p&gt;Moritz Krause &amp;amp; Torben Neumann, for bringing us the LLM suit for the game and mapping their threats to OWASP AISVS, AITG, Top 10 for LLM, Mitre Atlas, CWE, and STRIDE.&lt;/p&gt;

&lt;p&gt;Colin Watson for bringing us the Automated Threats suits and mapping his threats to OWASP Automated Threats to Web Applications.&lt;/p&gt;

&lt;p&gt;We also want to especially thank Ayman Algamal, Adarsh Kumar, Abhijit Sahoo, and Mradul Tiwari for helping develop the game, now available at copi.owasp.org, and for creating the help pages at cornucopia.owasp.org.&lt;/p&gt;

&lt;p&gt;And we want to thank all project leaders and contributors to the OWASP projects that have provided valuable input and guidance on the OWASP Top 10, OWASP AISVS, and the OWASP GenAI Security project. We also want to thank the people and contributors to Mitre's Common Attack Pattern Enumeration and Classification (CAPEC™) and Mitre Atlas™, and the Cloud Security Alliance for the use of the Cloud Controls Matrix, which are all used in the cross-references provided.&lt;/p&gt;

&lt;p&gt;In addition, we want to thank Anand kushwaha, Mahaboobunnisa Md for helping with the release of v3.0.0 and CyberSec Games for all the help and support with the printing and distribution of the 25th anniversary edition.&lt;/p&gt;
&lt;h2&gt;
  
  
  Final words
&lt;/h2&gt;

&lt;p&gt;OWASP Cornucopia welcomes any input or improvements you might be willing to share with us. For anyone wanting to share their opinion, please don't hesitate to &lt;a href="https://github.com/OWASP/cornucopia/issues" rel="noopener noreferrer"&gt;visit our repository&lt;/a&gt;, share your feedback, and, if appropriate, give us a star⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 340 chapters worldwide.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>gamedev</category>
      <category>appsec</category>
    </item>
    <item>
      <title>The Cornucopia of Gamified Threat Modeling</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Tue, 24 Mar 2026 09:55:15 +0000</pubDate>
      <link>https://dev.to/owasp/the-cornucopia-of-gamified-threat-modeling-1c9k</link>
      <guid>https://dev.to/owasp/the-cornucopia-of-gamified-threat-modeling-1c9k</guid>
      <description>&lt;p&gt;&lt;strong&gt;At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0: &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0" rel="noopener noreferrer"&gt;https://cornucopia.owasp.org/edition/webapp/VE2/3.0&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We would like to thank everyone who contributed to the translations for the new version of the card game and welcome you to review the text on the help pages themselves. Are there inconsistencies? Is there something you feel should be added or removed? If you find anything, please don't hesitate to contact us or raise an issue. Each page includes a "View source on GitHub" button that lets you quickly edit the text if you aren't pleased with it. All viewpoints and critiques are welcome as we are trying to create a home for gamified threat modelling.&lt;/p&gt;

&lt;p&gt;The new Website App Edition v3.0, available in 11 languages (EN, ES, FR, HI, NL, NO-NB, PT-PT,  PT-BR, RU, UK, HI), connects 202 CAPECs individually to a set of ASVS 5.0 requirements in relation to each of the cards. This means, even though you only have 80 cards, the website describes an exponential number of possible threats, making it the Cornucopia of website app threats. There is simply no end to the possibilities that your thoughts can take you while playing the game, yes, that's the Cornucopia way.&lt;br&gt;
But what if you want to focus on a specific CAPEC and find the related OWASP ASVS requirements? &lt;br&gt;
Go to a card, click on the CAPEC in the CAPEC map, and it will give you all the possible OWASP ASVS combinations, thereby connecting attack patterns and security requirements, making a thorough and deep website security requirement analysis possible while discussing a specific card. You can literally spend weeks analysing, playing, deciding for yourself "What can go wrong?", "What to do about it?", and even form yourself an opinion on whether you really did a good job (see: &lt;a href="https://github.com/adamshostack/4QuestionFrame" rel="noopener noreferrer"&gt;Shostack's Four Question Frame for Threat Modeling&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;Have we stopped there? Now we haven't! For each card, you also have the "OWASP Cheat Sheet Series Index". What is that? The "OWASP Cheat Sheet Series Index" is an OWASP index that connects each of the ASVS requirements with a set of OWASP Cheat Sheets that will give you advice on how to implement the specific OWASP ASVS requirement! Want to know how to do log protection according to "OWASP ASVS V16.4 - Log Protection"? No problem! The "OWASP ASVS (5.0) Cheat Sheet Series Index" displayed on the help pages for each card will take you to the collection of OWASP Cheat Sheets that is related to the requirement you are wondering about.&lt;/p&gt;

&lt;p&gt;But there is even more! What about STRIDE? What about Threat Modeling? Each card has a &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0#STRIDE" rel="noopener noreferrer"&gt;STRIDE section&lt;/a&gt;, a &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0#What-can-go-wrong?" rel="noopener noreferrer"&gt;"What can go wrong?"&lt;/a&gt; section and a &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;"What are we going to do about it?"&lt;/a&gt; section. &lt;/p&gt;

&lt;p&gt;This means that during your threat modeling, if you have questions about &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0#What-can-go-wrong?" rel="noopener noreferrer"&gt;"What can go wrong?"&lt;/a&gt; or &lt;a href="https://cornucopia.owasp.org/edition/webapp/VE2/3.0#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;"What are we going to do about it?"&lt;/a&gt; Just go to the individual card pages, and you will find what you are looking for!&lt;/p&gt;

&lt;p&gt;Now, you may be asking yourself, "That's it, right? No, it isn't, we have even moooooooore! &lt;/p&gt;
&lt;h2&gt;
  
  
  Threat Dragon and EoP Games
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" alt="Threat Dragon and EoP Games" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When choosing a tool for publishing our threat model, we chose &lt;a href="https://www.threatdragon.com/#/" rel="noopener noreferrer"&gt;OWASP Threat Dragon&lt;/a&gt;. OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application. It is used to create threat modeling diagrams and list threats for elements within the diagrams. Mike Goodwin created Threat Dragon as an open-source community project that provides an intuitive, accessible way to model threats.&lt;/p&gt;

&lt;p&gt;OWASP Threat Dragon has released this possibility in v2.6. This is just the start of integration between the two projects.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" alt="How to choose to create a OWASP Cornucopia threat model" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks to Gerardo Canedo and his students at Universidad Católica del Uruguay, it's now possible to create your OWASP Cornucopia Threat Model directly in OWASP Threat Dragon. When creating a new diagram for your threat model, simply choose to create an EoP Games diagram. We chose to call the diagram EoP Games for two reasons. One, OWASP Cornucopia is derived from the &lt;a href="https://shostack.org/games/elevation-of-privilege" rel="noopener noreferrer"&gt;Elevation of Privilege game&lt;/a&gt; created by Adam Shostack. Two, we don't want to stop with OWASP Cornucopia. We also want to add other EoP games, such as the original EoP Game.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" alt="Create a OWASP Cornucopia threat" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Once you have created an EoP Games diagram, you can add OWASP Cornucopia threats to your threat model. The specific threat you add will get a link reference to the &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#Threat-Modeling" rel="noopener noreferrer"&gt;OWASP Cornucopia website&lt;/a&gt;, where you will find guidance on threat modeling and STRIDE, which will help you in identifying what can go wrong and what to do about it. You can also find a &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;complete mapping&lt;/a&gt; to &lt;a href="https://cornucopia.owasp.org/taxonomy/asvs-4.0.3/02-authentication/05-credential-recovery#V2.5.2" rel="noopener noreferrer"&gt;OWASP ASVS&lt;/a&gt;, &lt;a href="https://devguide.owasp.org/en/04-design/02-web-app-checklist/06-digital-identity/#1-authentication-a" rel="noopener noreferrer"&gt;OWASP Developer Guide&lt;/a&gt;, and all &lt;a href="https://cornucopia.owasp.org/taxonomy/capec-3.9" rel="noopener noreferrer"&gt;relevant CAPECs&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" alt="OWASP Corncupia Website" width="800" height="737"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I want to express my sincere appreciation to Gerardo Canedo, Sebastian Feirres, and their students at Universidad Católica del Uruguay for making this possible. With their dedication and effort, OWASP Cornucopia wouldn’t have had this possibility.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faabcyoarlrl9ogkvw601.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faabcyoarlrl9ogkvw601.JPG" alt="Gerardo Canedo and his students at Universidad Católica del Uruguay" width="800" height="611"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Shostack's 4 Question Frame for Threat Modeling
&lt;/h2&gt;

&lt;p&gt;OWASP Cornucopia, together with OWASP Threat Dragon, is helping us in answering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What we are working on&lt;/li&gt;
&lt;li&gt;What can go wrong?&lt;/li&gt;
&lt;li&gt;What are we going to do about it?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;...but "Did we do a good enough job?"&lt;/p&gt;

&lt;p&gt;At Admincontrol, where I work, we have always sent an anonymous survey after every OWASP Cornucopia threat modeling session. The aggregate score for how satisfied respondents have been with all sessions we've held since we started OWASP Cornucopia in 2023 is 4.5 out of 5. When asked how relevant the session was to the participant's job, the average score was 4.7 out of 5. When asked whether the OWASP Cornucopia session helped the participants understand which security controls (mitigations) they need to implement/test, the score was 4.5. When asked whether the session improved the overall awareness of application security requirements, the score was 4.0. When asked, "Did we do a good job?", the score was 4.3. So for sure, we can do better!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn0iihqk4knhglpi3qo2l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn0iihqk4knhglpi3qo2l.png" alt="Relevant for your job" width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When asking the question, "Did we do a good enough job?", don’t just blurt it out during a session. Do you honestly think people will give you their honest criticism to your face directly? Send out an anonymous survey and ask for feedback!&lt;/p&gt;
&lt;h2&gt;
  
  
  How to get those requirements into your issue tracking software
&lt;/h2&gt;

&lt;p&gt;So you have done your threat modeling and security requirement analysis, what comes next? You need to create an issue that the development team can work on, and you need to add it to the development team's sprint. How do you do it? &lt;br&gt;
The OWASP Cornucopia project is creating a &lt;a href="https://cornucopia.owasp.org/api/docs" rel="noopener noreferrer"&gt;requirements API&lt;/a&gt; that lets you harvest the security requirements you want. After you have created your threat model in OWASP Threat Dragon, extract its JSON response, look up the threats you have identified, and find the corresponding security requirements by using the API, merge the results together, and generate your &lt;a href="https://cornucopia.owasp.org/how-to-play#Gameplay---Modelling-evil-user-stories" rel="noopener noreferrer"&gt;evil user stories&lt;/a&gt; by pushing the results to your issue tracking software just in time for the development team's next sprint.&lt;/p&gt;
&lt;h2&gt;
  
  
  How to get OWASP Cornucopia?
&lt;/h2&gt;

&lt;p&gt;The question you might be asking yourself is, "How are we going to be able to utilize these resources and play this game?" No problem! There are various ways you can do that, both online at &lt;a href="http://copi.owasp.org/" rel="noopener noreferrer"&gt;copi.owasp.org&lt;/a&gt; and in person, enjoying the presence of your colleagues, by &lt;a href="https://cybersecgames.com/products/owasp%C2%AE-cornucopia-3-0-website-app-edition-threat-modeling-cards-copy" rel="noopener noreferrer"&gt;buying a deck of cards&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;
  
  
  What is coming next...
&lt;/h2&gt;

&lt;p&gt;But what about DevOps? What about LLM and AI Agents? We are working on that too. The new &lt;a href="https://cornucopia.owasp.org/edition/companion" rel="noopener noreferrer"&gt;OWASP Cornucopia Companion Edition&lt;/a&gt;, that soon will be published, can be used alongside the OWASP Website App Edition and it comes with 6 new companion suits covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and  DevOps (DVO). A suit in the companion deck may replace (or be used in addition to) suites in the existing Website Edition so that the players can add a specific focus to their threat modeling: For example, say you are building an LLM application and want to perform threat modeling specifically for LLM. You would then use the OWASP Cornucopia Website Edition and the LLM companion suite as your elected OWASP Cornucopia focus area.&lt;/p&gt;

&lt;p&gt;OWASP Cornucopia welcomes any input or improvements you might be willing to share with us. For anyone wanting to share their opinion, please don't hesitate to &lt;a href="https://github.com/OWASP/cornucopia/issues" rel="noopener noreferrer"&gt;visit our repository&lt;/a&gt;, share your feedback, and, if appropriate, give us a star⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 250 chapters worldwide.&lt;/p&gt;

</description>
      <category>appsec</category>
      <category>security</category>
      <category>gamedev</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>OWASP Cornucopia is publishing it’s darkest secrets!</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Mon, 16 Feb 2026 06:39:00 +0000</pubDate>
      <link>https://dev.to/owasp/owasp-cornucopia-is-publishing-its-darkest-secrets-fjc</link>
      <guid>https://dev.to/owasp/owasp-cornucopia-is-publishing-its-darkest-secrets-fjc</guid>
      <description>&lt;p&gt;&lt;strong&gt;Why do we keep our darkest fears secret? Publish them, and bring light to the darkest corners of your web application.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When Adam Schostack + associates last year urged everyone to &lt;a href="https://shostack.org/blog/publish-your-threat-model/" rel="noopener noreferrer"&gt;publish their threat model&lt;/a&gt;, we thought, «What a wonderful idea!»&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fivcsnbnbtq4qs0t4xzc6.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fivcsnbnbtq4qs0t4xzc6.webp" alt="Publish your threat model, at https://shostack.org/blog/publish-your-threat-model/" width="800" height="300"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So we went ahead and did just that. At cornucopia.owasp.org, you can now &lt;a href="https://cornucopia.owasp.org/copi#Our-Threat-Model" rel="noopener noreferrer"&gt;find the threat model&lt;/a&gt; for the &lt;a href="https://copi.owasp.org/" rel="noopener noreferrer"&gt;OWASP Cornucopia Game Engine, Copi&lt;/a&gt;.&lt;br&gt;
There we have listed all our darkest fears and secrets. Darkness is not a force of its own; it is simply the absence of light. When light is shed on our doubts and fears, making them visible, we find solutions and become stronger. This is why publishing your threat model is essential. If you refuse to disclose your vulnerabilities to anyone, they become liabilities that may one day lead to doubts, lies, and perhaps even conspiracies and litigation. Therefore, before building software, build trust and make it clear what others need to be aware of.&lt;/p&gt;
&lt;h2&gt;
  
  
  Threat Dragon and EoP Games
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1ry2rze9wnftocimdkyo.png" alt="Threat Dragon and EoP Games" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When choosing a tool for publishing our threat model, we chose &lt;a href="https://www.threatdragon.com/#/" rel="noopener noreferrer"&gt;OWASP Threat Dragon&lt;/a&gt;. OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application. It is used to create threat modeling diagrams and list threats for elements within the diagrams. Mike Goodwin created Threat Dragon as an open-source community project that provides an intuitive, accessible way to model threats.&lt;/p&gt;

&lt;p&gt;OWASP Threat Dragon will release this possibility in v2.6, which is due to be released in week 9, but already now, you can try it out on their &lt;a href="https://www.threatdragon.com/#/" rel="noopener noreferrer"&gt;demo site&lt;/a&gt;. This is just the start of integration between the two projects; more is to come. OWASP Threat Dragon V2.6 will come out with all sorts of exciting features. For a full list, have a look at their current &lt;a href="https://github.com/OWASP/threat-dragon/issues?q=label%3Aversion-2.6" rel="noopener noreferrer"&gt;v2.6 roadmap&lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fl25mz5xxzbt0a8t5627g.png" alt="How to choose to create a OWASP Cornucopia threat model" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks to Gerardo Canedo and his students at Universidad Católica del Uruguay, it's now possible to create your OWASP Cornucopia Threat Model directly in OWASP Threat Dragon. When creating a new diagram for your threat model, simply choose to create an EoP Games diagram. We chose to call the diagram EoP Games for two reasons. One, OWASP Cornucopia is derived from the &lt;a href="https://shostack.org/games/elevation-of-privilege" rel="noopener noreferrer"&gt;Elevation of Privilege game&lt;/a&gt; created by Adam Shostack. Two, we don't want to stop with OWASP Cornucopia. We also want to add other EoP games, such as the original EoP Game.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1zl30hc63fie1wg6y7e3.png" alt="Create a OWASP Cornucopia threat" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Once you have created an EoP Games diagram, you can add OWASP Cornucopia threats to your threat model. The specific threat you add will get a link reference to the &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#Threat-Modeling" rel="noopener noreferrer"&gt;OWASP Cornucopia website&lt;/a&gt;, where you will find guidance on threat modeling and STRIDE, which will help you in identifying what can go wrong and what to do about it. You can also find a &lt;a href="https://cornucopia.owasp.org/edition/webapp/AT3/2.2/en#What-are-we-going-to-do-about-it?" rel="noopener noreferrer"&gt;complete mapping&lt;/a&gt; to &lt;a href="https://cornucopia.owasp.org/taxonomy/asvs-4.0.3/02-authentication/05-credential-recovery#V2.5.2" rel="noopener noreferrer"&gt;OWASP ASVS&lt;/a&gt;, &lt;a href="https://devguide.owasp.org/en/04-design/02-web-app-checklist/06-digital-identity/#1-authentication-a" rel="noopener noreferrer"&gt;OWASP Developer Guide&lt;/a&gt;, and all &lt;a href="https://cornucopia.owasp.org/taxonomy/capec-3.9" rel="noopener noreferrer"&gt;relevant CAPECs&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9mvjvggcpwkh58fix1bc.png" alt="OWASP Corncupia Website" width="800" height="737"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I want to express my sincere appreciation to Gerardo Canedo, Sebastian Feirres, and their students at Universidad Católica del Uruguay for making this possible. With their dedication and effort, OWASP Cornucopia wouldn’t have had this possibility.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faabcyoarlrl9ogkvw601.JPG" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Faabcyoarlrl9ogkvw601.JPG" alt="Gerardo Canedo and his students at Universidad Católica del Uruguay" width="800" height="611"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Shostack's 4 Question Frame for Threat Modeling
&lt;/h2&gt;

&lt;p&gt;OWASP Cornucopia, together with OWASP Threat Dragon, is helping us in answering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What we are working on&lt;/li&gt;
&lt;li&gt;What can go wrong?&lt;/li&gt;
&lt;li&gt;What are we going to do about it?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;...but "Did we do a good enough job?"&lt;/p&gt;

&lt;p&gt;At Admincontrol, where I work, we have always sent an anonymous survey after every OWASP Cornucopia threat modeling session. The aggregate score for how satisfied respondents have been with all sessions we've held since we started OWASP Cornucopia in 2023 is 4.5 out of 5. When asked how relevant the session was to the participant's job, the average score was 4.7 out of 5. When asked whether the OWASP Cornucopia session helped the participants understand which security controls (mitigations) they need to implement/test, the score was 4.5. When asked whether the session improved the overall awareness of application security requirements, the score was 4.0. When asked, "Did we do a good job?", the score was 4.3. So for sure, we can do better!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn0iihqk4knhglpi3qo2l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn0iihqk4knhglpi3qo2l.png" alt="Relevant for your job" width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When asking the question, "Did we do a good enough job?", don’t just blurt it out during a session. Do you honestly think people will give you their honest criticism to your face directly? Send out an anonymous survey and ask for feedback!&lt;/p&gt;

&lt;p&gt;OWASP Cornucopia welcomes any input or improvements you might be willing to share with us regarding our current threat model. Arguably, we created the system before we were able to identify all our threats, and several improvements need to be made to properly balance the inherent risks of compromise against the current security controls. For anyone hosting the game engine, please take this into account. For anyone wanting to share their opinion, please don't hesitate to &lt;a href="https://github.com/OWASP/cornucopia/issues" rel="noopener noreferrer"&gt;visit our repository&lt;/a&gt;, share your feedback, and, if appropriate, give us a star⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 250 chapters worldwide.&lt;/p&gt;

</description>
      <category>security</category>
      <category>appsec</category>
      <category>agile</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Are you the next card game designer for OWASP Cornucopia Website Edition v3.0?
Then get in touch with us for fame and glory!</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Thu, 13 Nov 2025 14:38:16 +0000</pubDate>
      <link>https://dev.to/sydseter/are-you-the-next-card-game-designer-for-owasp-cornucopia-website-edition-v30-then-get-in-touch-2em</link>
      <guid>https://dev.to/sydseter/are-you-the-next-card-game-designer-for-owasp-cornucopia-website-edition-v30-then-get-in-touch-2em</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m" class="crayons-story__hidden-navigation-link"&gt;OWASP Cornucopia 3.0 - A call for card game designers!&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/owasp"&gt;
            &lt;img alt="OWASP® Foundation logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3468%2F0b3561bb-9ac3-413f-baaa-5014181e4b4d.jpg" class="crayons-logo__image" width="400" height="400"&gt;
          &lt;/a&gt;

          &lt;a href="/sydseter" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" alt="sydseter profile" class="crayons-avatar__image" width="799" height="747"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sydseter" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Johan Sydseter
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Johan Sydseter
                
                
              
              &lt;div id="story-author-preview-content-3019822" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sydseter" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" class="crayons-avatar__image" alt="" width="799" height="747"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Johan Sydseter&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/owasp" class="crayons-story__secondary fw-medium"&gt;OWASP® Foundation&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Nov 13 '25&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m" id="article-link-3019822"&gt;
          OWASP Cornucopia 3.0 - A call for card game designers!
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/gamedev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;gamedev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/design"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;design&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>gamedev</category>
      <category>security</category>
      <category>design</category>
      <category>webdev</category>
    </item>
    <item>
      <title>OWASP Cornucopia 3.0 - A call for card game designers!</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Thu, 13 Nov 2025 12:24:59 +0000</pubDate>
      <link>https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m</link>
      <guid>https://dev.to/owasp/owasp-cornucopia-30-a-call-for-card-game-designers-1j1m</guid>
      <description>&lt;h2&gt;
  
  
  &lt;em&gt;Would you like to be our card game designer for the OWASP Cornucopia Website Edition v3.0?&lt;/em&gt;
&lt;/h2&gt;

&lt;p&gt;We are close to releasing the next version of &lt;a href="https://cornucopia.owasp.org/cards" rel="noopener noreferrer"&gt;OWASP Cornucopia Website Edition v3.0&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We wonder whether there are some brilliant designers out there who would like to volunteer to create the motifs for the 80 cards in OWASP's very popular threat modeling card games for website applications?&lt;/p&gt;

&lt;p&gt;OWASP® Cornucopia is a threat modeling tool in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional, and formal development processes. It strives to be language, platform, and technology-agnostic.&lt;/p&gt;

&lt;p&gt;It’s one of the few tools that connects threat modeling with OWASP ASVS, SAFECode, STRIDE, OWASP DevGuide, and CAPEC, helping to identify security requirements, develop a secure design, and create a threat model without prior knowledge of these frameworks. &lt;/p&gt;

&lt;p&gt;We are now creating the next version of the website app game. The new version will feature new cards and text that cover all of the requirements in OWASP ASVS 5.0 and connect these to more than 210 unique common attack patterns (CAPEC).&lt;/p&gt;

&lt;p&gt;The first edition was created in August 2012, released as v1.0 in February 2013, and has undergone several minor updates/releases over the subsequent ten years. This has been substantially updated in today’s release of v3.0, with the most noticeable change being the update of the OWASP ASVS mapping from ASVS v4.0 to v5.0. The card game comes in two physical sizes. The smaller ones are often referred to as “bridge-sized cards” and the larger ones as “Tarot-sized cards”. All these v3.0 files will be immediately available in nine languages (English, Spanish, French, Dutch, Norwegian, Portuguese, Italian, Russian, and Hungarian) due to the efforts of past and current volunteers.&lt;/p&gt;

&lt;p&gt;Don't hesitate to get in touch &lt;a href="https://www.linkedin.com/in/sydseter/" rel="noopener noreferrer"&gt;with us&lt;/a&gt; for fame and glory.&lt;/p&gt;




&lt;p&gt;Uncover the security flaws in your software's design before the bad guys do it for you! Get your team together on a call or in a room and use OWASP Cornucopia Web &amp;amp; Mobile, Elevation of Privilege or Elevation of MLSec and OWASP Cumulus to secure your AI models and Cloud infrastructure respectively and guide your threat modelling at &lt;a href="https://copi.owasp.org" rel="noopener noreferrer"&gt;copi.owasp.org&lt;/a&gt;, and if you visit our &lt;a href="https://github.com/OWASP/cornucopia" rel="noopener noreferrer"&gt;code repository&lt;/a&gt; please give us a star ⭐️.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/XXTPXozIHow" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;




&lt;p&gt;&lt;a href="https://owasp.org" rel="noopener noreferrer"&gt;OWASP&lt;/a&gt; is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 250 chapters worldwide.&lt;/p&gt;

</description>
      <category>gamedev</category>
      <category>security</category>
      <category>design</category>
      <category>webdev</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Johan Sydseter</dc:creator>
      <pubDate>Wed, 08 Oct 2025 20:02:20 +0000</pubDate>
      <link>https://dev.to/sydseter/-2onl</link>
      <guid>https://dev.to/sydseter/-2onl</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap" class="crayons-story__hidden-navigation-link"&gt;How do you get your dev team to shift left by themselves for real?&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/owasp"&gt;
            &lt;img alt="OWASP® Foundation logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F3468%2F0b3561bb-9ac3-413f-baaa-5014181e4b4d.jpg" class="crayons-logo__image" width="400" height="400"&gt;
          &lt;/a&gt;

          &lt;a href="/sydseter" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" alt="sydseter profile" class="crayons-avatar__image" width="799" height="747"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/sydseter" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Johan Sydseter
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Johan Sydseter
                
                
              
              &lt;div id="story-author-preview-content-2882751" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/sydseter" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1603787%2F9b5df7e9-94c8-4174-ab30-03636c91835f.jpg" class="crayons-avatar__image" alt="" width="799" height="747"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Johan Sydseter&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/owasp" class="crayons-story__secondary fw-medium"&gt;OWASP® Foundation&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Oct 3 '25&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap" id="article-link-2882751"&gt;
          How do you get your dev team to shift left by themselves for real?
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/devops"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;devops&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/gamedev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;gamedev&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            6 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>devops</category>
      <category>security</category>
      <category>ai</category>
      <category>gamedev</category>
    </item>
  </channel>
</rss>
